Back

MEDIUM

firefox/seamonkey: mail application launch when IFRAME element has a mailto: URI in its SRC attribute

Published May 20, 2010

Description

Mozilla Firefox 3.6.x, 3.5.x, 3.0.19, and earlier, and SeaMonkey, executes a mail application in situations where an IFRAME element has a mailto: URL in its SRC attribute, which allows remote attackers to cause a denial of service (excessive application launches) via an HTML document with many IFRAME elements.

Affected products

Remediation

Red Hat statement

The Red Hat Security Response Team does not consider a user assisted denial of service (and potential crash) of end user application, such a Firefox, to be a security issue.

Metrics

Weaknesses (1)

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published May 20, 2010
Updated Aug 7, 2024
Reserved May 20, 2010
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity n/a
Public date May 18, 2010